Welltok, Inc.
bd_2fa5485914c25161 · schema v1 · pii pii-v1
Welltok, Inc. issued a supplemental notice to the Washington State Attorney General regarding a data event involving its MOVEit Transfer server. An unknown actor exploited software vulnerabilities to access the server on May 30, 2023, and exfiltrated data including names, DOBs, SSNs, and PHI. Welltok discovered the potential compromise on July 26, 2023. Approximately 48,257 Washington residents were notified starting December 13, 2023. Welltok provided credit monitoring via Experian.
J jump to incidentP pin to compareR raw source
Incident timeline
May 30, 2023
Begins
Jul 26, 2023
Discovered
Dec 15, 2023
Filed
vs. sector median
+2 wks slower
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- HHS OCRbd_97bf9bf4880c835a2023-12-21 · +6dVerified
Filing propagation · 2 filings · 2 states
View merged incident ↗Pattern: first filing Dec 15 (WA), last Dec 21 (KY) — a 6-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.